CVE-2010-3117: Critical severity Google Chrome vulnerability
Published Aug 24, 2010
·Updated
Google Chrome before 5.0.375.127 does not properly implement the notifications feature, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via unknown vectors.
Affected Software
1 affected component
Google Chrome<5.0.375.127
Remediation
Patch Available
Event History
Aug 24, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
Which Chrome installations are affected?
Google Chrome versions before 5.0.375.127 are affected. The issue is in the browser's notifications feature.
2
Does exploitation require local access or user authentication?
No. The supplied vector indicates network attack access, low attack complexity, and no authentication requirement.
3
What is the confirmed impact?
A remote attacker can cause the Chrome application to crash, resulting in denial of service. The advisory also notes the possibility of other unspecified impact.
4
What should be done to remediate this issue?
Apply the available patch by updating Chrome to version 5.0.375.127 or later.